This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Internet address hijack

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This is the OTListIT. On my Computer I Have: Norman AV Norman Adaware Pro Norman Malware Cleaner Lavasoft Adaware Pro I need help in disabling these as I want to be sure that I am doing it properly. Thanks. ========== OTLISTIT ========== Process Explorer.EXE killed successfully! Process SYS32DLL.exe killed successfully! Service\Driver perfmons deleted successfully. File File not found not found. Service\Driver Print Service deleted successfully. File File not found not found. Service\Driver Remote Manager deleted successfully. File File not found not found. Service\Driver Indexingbox deleted successfully. File File not found not found. Service\Driver NETDown deleted successfully. File File not found not found. Service\Driver WindowsKernel deleted successfully. File File not found not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C7EFE99-C71F-48b8-8CC8-BA506CA76A33}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C7EFE99-C71F-48b8-8CC8-BA506CA76A33}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\pp deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\sysldtray deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\SYS32DLL deleted successfully. C:\WINDOWS\System32\SYS32DLL.exe moved successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableTaskMgr deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\WINDOWS\system32\pavuppad.exe deleted successfully. File move failed. C:\WINDOWS\system32\pavuppad.exe scheduled to be moved on reboot. LoadLibrary failed for C:\WINDOWS\System32\pfxzmtsmtspm.dll C:\WINDOWS\System32\pfxzmtsmtspm.dll NOT unregistered. C:\WINDOWS\System32\pfxzmtsmtspm.dll moved successfully. LoadLibrary failed for C:\WINDOWS\System32\sfxzmtforum.dll C:\WINDOWS\System32\sfxzmtforum.dll NOT unregistered. C:\WINDOWS\System32\sfxzmtforum.dll moved successfully. LoadLibrary failed for C:\WINDOWS\System32\pfxzmtymsg.dll C:\WINDOWS\System32\pfxzmtymsg.dll NOT unregistered. C:\WINDOWS\System32\pfxzmtymsg.dll moved successfully. LoadLibrary failed for C:\WINDOWS\System32\pfxzmticq.dll C:\WINDOWS\System32\pfxzmticq.dll NOT unregistered. C:\WINDOWS\System32\pfxzmticq.dll moved successfully. LoadLibrary failed for C:\WINDOWS\System32\pfxzmtgtal.dll C:\WINDOWS\System32\pfxzmtgtal.dll NOT unregistered. C:\WINDOWS\System32\pfxzmtgtal.dll moved successfully. LoadLibrary failed for C:\WINDOWS\System32\pfxzmtaim.dll C:\WINDOWS\System32\pfxzmtaim.dll NOT unregistered. C:\WINDOWS\System32\pfxzmtaim.dll moved successfully. LoadLibrary failed for C:\WINDOWS\System32\pfxzmtwbmail.dll C:\WINDOWS\System32\pfxzmtwbmail.dll NOT unregistered. C:\WINDOWS\System32\pfxzmtwbmail.dll moved successfully. LoadLibrary failed for C:\WINDOWS\System32\pfxzmtsmt.dll C:\WINDOWS\System32\pfxzmtsmt.dll NOT unregistered. C:\WINDOWS\System32\pfxzmtsmt.dll moved successfully. LoadLibrary failed for C:\WINDOWS\System32\pfxzmtzpurse.dll C:\WINDOWS\System32\pfxzmtzpurse.dll NOT unregistered. C:\WINDOWS\System32\pfxzmtzpurse.dll moved successfully. LoadLibrary failed for C:\WINDOWS\System32\pfxzmtrpurse.dll C:\WINDOWS\System32\pfxzmtrpurse.dll NOT unregistered. C:\WINDOWS\System32\pfxzmtrpurse.dll moved successfully. LoadLibrary failed for C:\WINDOWS\System32\pfxzmtfpurse.dll C:\WINDOWS\System32\pfxzmtfpurse.dll NOT unregistered. C:\WINDOWS\System32\pfxzmtfpurse.dll moved successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== File\Folder C:\WINDOWS\system32\SYS32DLL.exe not found. C:\WINDOWS\System32\CF20455.exe moved successfully. C:\WINDOWS\System32\CF19610.exe moved successfully. C:\WINDOWS\t55ft2692f44.dat moved successfully. C:\WINDOWS\9g2234wesdf3dfgjf23 moved successfully. C:\WINDOWS\System32\218538 moved successfully. Folder move failed. C:\WINDOWS\System32\bookls scheduled to be moved on reboot. C:\WINDOWS\internat.exe moved successfully. C:\WINDOWS\System32\inform.dat moved successfully. C:\WINDOWS\System32\pmx moved successfully. C:\WINDOWS\System32\mywebhit.ini moved successfully. C:\WINDOWS\imsins.BAK moved successfully. ========== COMMANDS ========== User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\nvcbin.def.fa1b0d9b.tmp scheduled to be deleted on reboot. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Network Service Temp folder emptied. Network Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.15.8 log created on 05172009_091909
Hi ADS,


Norman antivirus


-Right click the N-icon
-Open the Norman Configuration Editor.
-Select the Components icon.
-Select the Start tab.
-Uncheck the box for Internet Protection.
-Click Save

Ad-Aware Pro is the same steps as AD-AWARE AD-WATCH, so that should be Ok.

Norman Malware Cleaner is an on demand program, so it won't be a problem

Norman Adaware Pro, I don't use it but try this

Double click the Norman Ad-Aware icon on your desktop to launch the program, and check in these sections Ad-aware SE status or General settings
The only issue is my Lavasoft adaware. I do not have an icon in my system tray only on my desktop. When I open this up I do not have an Active and Automatic option. I ahve managed to turn the Adwatch live off. Will this do? Thanks again.
Please find the ComboFix log below.

ComboFix 09-05-16.05 - Allen Sheena 17/05/2009 18:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1022.517 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: Norman Security Suite *On-access scanning disabled* (Updated) {EB9EFB40-AE72-4C43-B204-0FCD0E92D5F1}
FW: Norman Security Suite *disabled* {83B29CE9-9DE2-2CB5-9AB3-780D70FF12B0}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\CrucialSoft Ltd
c:\documents and settings\Allen Sheena\Application Data\wiaserva.log
c:\documents and settings\NetworkService\Application Data\wiaserva.log
c:\program files\Common\helper.sig
c:\program files\Video Add-on
c:\windows\IE4 Error Log.txt
c:\windows\system32\dz1.txt
c:\windows\system32\imvalid.ico
c:\windows\system32\imvalid.ico.bak0
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\mywebhit.ini.tmp
c:\windows\system32\p1.txt
c:\windows\system32\r24.txt
c:\windows\system32\sdra64.exe
c:\windows\system32\winio.dll
c:\windows\system32\winio.vxd

.
((((((((((((((((((((((((( Files Created from 2009-04-17 to 2009-05-17 )))))))))))))))))))))))))))))))
.

2009-05-15 20:44 . 2009-05-15 20:44 ——– d—–w C:\_OTListIt
2009-05-15 12:00 . 2009-05-15 11:42 15688 —-a-w c:\windows\system32\lsdelete.exe
2009-05-15 11:43 . 2009-05-15 11:42 64160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-05-15 11:39 . 2009-05-15 11:39 ——– dc-h–w c:\documents and settings\All Users\Application Data\{2BAE6915-8510-4B9F-B498-02DA86258AA0}
2009-05-15 11:39 . 2009-05-15 11:39 ——– d—–w c:\program files\Lavasoft
2009-05-15 11:39 . 2009-05-15 11:39 ——– d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2009-05-12 23:09 . 2009-05-17 17:09 ——– d-sh–w c:\windows\system32\bookls

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-17 17:09 . 2009-04-06 09:06 ——– d—–w c:\program files\Norman
2009-05-17 17:03 . 2009-03-07 00:21 ——– d—–w c:\program files\Common
2009-04-14 08:12 . 2005-10-21 00:05 ——– d—–w c:\program files\Common Files\Adobe
2009-03-07 01:07 . 2009-03-07 01:07 81 —-a-w C:\CTX.DAT
2009-03-06 14:22 . 2004-08-04 12:00 284160 —-a-w c:\windows\system32\pdh.dll
2009-02-27 11:12 . 2007-11-04 02:30 173473 —-a-w c:\windows\system32\mssock.dat
2009-02-20 08:10 . 2004-08-04 12:00 666112 —-a-w c:\windows\system32\wininet.dll
2009-02-20 08:10 . 2004-08-04 12:00 81920 —-a-w c:\windows\system32\ieencode.dll
2009-04-04 12:22 . 2008-04-24 18:36 67688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2009-04-04 12:22 . 2008-04-24 18:36 54368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2009-04-04 12:22 . 2008-04-24 18:36 34944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2009-04-04 12:22 . 2008-04-24 18:36 46712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2009-04-04 12:22 . 2008-04-24 18:36 172136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-21 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
"DSL Connection Manager"="c:\program files\INTEL\DSLSetup\ProDsl.exe" [2007-10-22 65536]
"AWMON"="f:\norman ad-aware se professional\Ad-Watch.exe" [2004-09-21 538112]
"EPSON Stylus Photo R800"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9YE.EXE" [2005-01-13 98304]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-24 185896]
"Acrobat Assistant 7.0"="f:\adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-01-26 495616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"Norman ZANDA"="c:\program files\Norman\Npm\Bin\ZLH.EXE" [2009-02-11 187504]
"NPCTray"="c:\program files\Norman\npc\bin\npc_tray.exe" [2007-09-17 126008]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-04-15 77824]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-22 1622016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2008-8-6 25214]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-10-25 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
InterVideo WinCinema Manager.lnk - f:\intervideo\Common\Bin\WinCinemaMgr.exe [2005-10-25 106496]
Supero Doctor III Client.lnk - c:\program files\SUPERMICRO\SDIII\SuperoDoctor.exe [2005-10-18 397312]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"EnableProfileQuota"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,c:\windows\system32\pavuppad.exe,"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll
"wave2"= serwvdrv.dll
"wave3"= serwvdrv.dll
"wave4"= serwvdrv.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"f:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=

P2 NPFSvc32;Norman Personal Firewall Service;c:\program files\Norman\Npf\Bin\npfsvc32.exe [06/04/2009 10:07 597104]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [15/05/2009 12:43 64160]
R0 NDIS_RD;Norman Firewall NDIS driver;c:\windows\system32\drivers\ndis_rd.sys [06/04/2009 10:07 79752]
R1 ISAIONT;ISAIONT;c:\windows\system32\drivers\IsaIoNt.sys [18/10/2005 14:19 3853]
R1 MemMapNt;MemMapNt;c:\windows\system32\drivers\memmapnt.sys [18/10/2005 14:19 3908]
R1 NGS;Norman General Security Driver;c:\program files\Norman\Ngs\Bin\ngs.sys [06/04/2009 10:18 22712]
R1 NPROSEC;Norman Security driver;c:\program files\Norman\Ngs\Bin\nprosec.sys [06/04/2009 10:07 53816]
R1 SMBus;SMBus;c:\windows\system32\drivers\smbus.sys [18/10/2005 14:19 9984]
R1 TDI_RD;Norman Firewall TDI driver;c:\windows\system32\drivers\tdi_rd.sys [06/04/2009 10:07 74624]
R2 Ndiskio;Ndiskio;c:\program files\Norman\Nse\Bin\Ndiskio.sys [06/04/2009 10:07 20448]
R2 NPROSECSVC;Norman Security service;c:\program files\Norman\Ngs\Bin\nprosec.exe [06/04/2009 10:07 121912]
R2 NVOY;Norman Resource Provider;c:\program files\Norman\Npm\Bin\nvoy.exe [06/04/2009 10:07 126008]
R2 SuperMicro Health Assistant;SuperMicro Health Assistant;c:\program files\SUPERMICRO\SDIII\NTService.exe [18/10/2005 14:19 131072]
R2 Supero SD3Service Daemon;Supero SD3Service Daemon;c:\windows\system32\SD3Service.exe [18/10/2005 14:19 40960]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]
R2 Xitami;Xitami Web Server;c:\program files\SUPERMICRO\SDIII\xitami\xiwinnt.exe [18/10/2005 14:19 552960]
R3 NPC;Norman Parental Control;c:\program files\Norman\Npc\Bin\npcsvc32.exe [06/04/2009 10:07 416880]
R3 nsesvc;Norman Scanner Engine Service;c:\program files\Norman\Nse\Bin\Nsesvc.exe [15/05/2009 08:52 310328]
R3 NUAA;Norman User Activity Agent;c:\program files\Norman\Npc\Bin\nuaa.exe [06/04/2009 10:07 121912]
R3 Scheduler;Norman Scheduler Service;c:\program files\Norman\Npm\Bin\scheduler.exe [13/05/2009 10:33 130104]
R3 scsiscan;SCSI Scanner Driver;c:\windows\system32\drivers\scsiscan.sys [30/10/2005 13:42 11520]
S1 superbmc;superbmc;c:\windows\system32\drivers\SUPERBMC.SYS [18/10/2005 14:19 14174]
S2 IPSES;IPSES;c:\windows\System32\svchost.exe -k netsvcs [04/08/2004 13:00 14336]
S2 P32LOAD;Intel® AnyPoint® 3240 USB Modem Firmware Loader;c:\windows\system32\drivers\p31usbld.sys [21/10/2005 19:32 18906]
S3 EPUSBDSK;EPSON USB Mass Storage Driver;c:\windows\system32\drivers\EPUSBDSK.sys [06/12/2005 13:17 29983]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [03/02/2008 15:09 13352]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [19/01/2009 15:35 953168]
S3 NvcMFlt;NvcMFlt;c:\windows\system32\drivers\nvcw32mf.sys [06/04/2009 10:07 19512]
S3 nvcoas;Norman Virus Control on-access component;c:\program files\Norman\nvc\bin\Nvcoas.exe [06/04/2009 10:07 195640]
S3 NVCScheduler;Norman Virus Control Scheduler;"c:\program files\Norman\Npm\Bin\Nvcsched.exe" –> c:\program files\Norman\Npm\Bin\Nvcsched.exe [?]
S3 PRO3200P;Intel® USB ADSL Modem;c:\windows\system32\drivers\p32d2kp.sys [27/04/2002 04:23 530785]
S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);c:\windows\system32\drivers\sea1bus.sys [12/06/2007 18:37 61536]
S3 sea1mdfl;Sony Ericsson Device 0A1 USB WMC Modem Filter;c:\windows\system32\drivers\sea1mdfl.sys [12/06/2007 18:37 9360]
S3 sea1mdm;Sony Ericsson Device 0A1 USB WMC Modem Driver;c:\windows\system32\drivers\sea1mdm.sys [12/06/2007 18:37 97088]
S3 sea1mgmt;Sony Ericsson Device 0A1 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\sea1mgmt.sys [12/06/2007 18:37 88624]
S3 sea1nd5;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (NDIS);c:\windows\system32\drivers\sea1nd5.sys [12/06/2007 18:38 18704]
S3 sea1obex;Sony Ericsson Device 0A1 USB WMC OBEX Interface;c:\windows\system32\drivers\sea1obex.sys [12/06/2007 18:37 86432]
S3 sea1unic;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (WDM);c:\windows\system32\drivers\sea1unic.sys [12/06/2007 18:37 90800]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
IPSES

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2E1A9DE4-ADA0-4501-A46E-6633CDB01654}]
rundll32 magks32.dll,InitO
.
Contents of the 'Scheduled Tasks' folder

2009-05-17 c:\windows\Tasks\Ad-Aware Update (Daily).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-19 11:42]

2009-05-17 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-ATIPTA - c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
HKU-Default-Run-internat - c:\windows\internat.exe
Notify-AtiExtEvent - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://discography.ledzeppelin.com/discography.html
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: Convert link target to Adobe PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - e:\micros~1\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\Norman\npc\bin\nlf.dll
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.co.uk/scan_uk/scan8/oscan8.cab
FF - ProfilePath - c:\documents and settings\Allen Sheena\Application Data\Mozilla\Firefox\Profiles\op6y78jg.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: network.proxy.http - localhost
FF - prefs.js: network.proxy.http_port - 7171
FF - prefs.js: network.proxy.type - 1
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\qfaservices.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-17 18:11
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\Norman\Npm\Bin\elogsvc.exe
c:\program files\Norman\Npm\Bin\Zanda.exe
c:\program files\Norman\Npf\Bin\npfuser.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Teleca Shared\Generic.exe
c:\program files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\WinVNC.exe
c:\program files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
c:\program files\Norman\Npm\Bin\Njeeves.exe
c:\program files\Norman\nvc\bin\Nip.exe
.
**************************************************************************
.
Completion time: 2009-05-17 18:14 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-17 17:13

Pre-Run: 9,013,063,680 bytes free
Post-Run: 9,045,110,784 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

Current=1 Default=1 Failed=3 LastKnownGood=4 Sets=,1,3,4,5,6,7,8,9
235 — E O F — 2009-05-13 07:43
Please find the ComboFix log below.

ComboFix 09-05-16.05 - Allen Sheena 17/05/2009 18:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1022.517 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: Norman Security Suite *On-access scanning disabled* (Updated) {EB9EFB40-AE72-4C43-B204-0FCD0E92D5F1}
FW: Norman Security Suite *disabled* {83B29CE9-9DE2-2CB5-9AB3-780D70FF12B0}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\CrucialSoft Ltd
c:\documents and settings\Allen Sheena\Application Data\wiaserva.log
c:\documents and settings\NetworkService\Application Data\wiaserva.log
c:\program files\Common\helper.sig
c:\program files\Video Add-on
c:\windows\IE4 Error Log.txt
c:\windows\system32\dz1.txt
c:\windows\system32\imvalid.ico
c:\windows\system32\imvalid.ico.bak0
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\mywebhit.ini.tmp
c:\windows\system32\p1.txt
c:\windows\system32\r24.txt
c:\windows\system32\sdra64.exe
c:\windows\system32\winio.dll
c:\windows\system32\winio.vxd

.
((((((((((((((((((((((((( Files Created from 2009-04-17 to 2009-05-17 )))))))))))))))))))))))))))))))
.

2009-05-15 20:44 . 2009-05-15 20:44 ——– d—–w C:\_OTListIt
2009-05-15 12:00 . 2009-05-15 11:42 15688 —-a-w c:\windows\system32\lsdelete.exe
2009-05-15 11:43 . 2009-05-15 11:42 64160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-05-15 11:39 . 2009-05-15 11:39 ——– dc-h–w c:\documents and settings\All Users\Application Data\{2BAE6915-8510-4B9F-B498-02DA86258AA0}
2009-05-15 11:39 . 2009-05-15 11:39 ——– d—–w c:\program files\Lavasoft
2009-05-15 11:39 . 2009-05-15 11:39 ——– d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2009-05-12 23:09 . 2009-05-17 17:09 ——– d-sh–w c:\windows\system32\bookls

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-17 17:09 . 2009-04-06 09:06 ——– d—–w c:\program files\Norman
2009-05-17 17:03 . 2009-03-07 00:21 ——– d—–w c:\program files\Common
2009-04-14 08:12 . 2005-10-21 00:05 ——– d—–w c:\program files\Common Files\Adobe
2009-03-07 01:07 . 2009-03-07 01:07 81 —-a-w C:\CTX.DAT
2009-03-06 14:22 . 2004-08-04 12:00 284160 —-a-w c:\windows\system32\pdh.dll
2009-02-27 11:12 . 2007-11-04 02:30 173473 —-a-w c:\windows\system32\mssock.dat
2009-02-20 08:10 . 2004-08-04 12:00 666112 —-a-w c:\windows\system32\wininet.dll
2009-02-20 08:10 . 2004-08-04 12:00 81920 —-a-w c:\windows\system32\ieencode.dll
2009-04-04 12:22 . 2008-04-24 18:36 67688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2009-04-04 12:22 . 2008-04-24 18:36 54368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2009-04-04 12:22 . 2008-04-24 18:36 34944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2009-04-04 12:22 . 2008-04-24 18:36 46712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2009-04-04 12:22 . 2008-04-24 18:36 172136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-21 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
"DSL Connection Manager"="c:\program files\INTEL\DSLSetup\ProDsl.exe" [2007-10-22 65536]
"AWMON"="f:\norman ad-aware se professional\Ad-Watch.exe" [2004-09-21 538112]
"EPSON Stylus Photo R800"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9YE.EXE" [2005-01-13 98304]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-24 185896]
"Acrobat Assistant 7.0"="f:\adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-01-26 495616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"Norman ZANDA"="c:\program files\Norman\Npm\Bin\ZLH.EXE" [2009-02-11 187504]
"NPCTray"="c:\program files\Norman\npc\bin\npc_tray.exe" [2007-09-17 126008]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-04-15 77824]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-22 1622016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2008-8-6 25214]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-10-25 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
InterVideo WinCinema Manager.lnk - f:\intervideo\Common\Bin\WinCinemaMgr.exe [2005-10-25 106496]
Supero Doctor III Client.lnk - c:\program files\SUPERMICRO\SDIII\SuperoDoctor.exe [2005-10-18 397312]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"EnableProfileQuota"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,c:\windows\system32\pavuppad.exe,"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll
"wave2"= serwvdrv.dll
"wave3"= serwvdrv.dll
"wave4"= serwvdrv.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"f:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=

P2 NPFSvc32;Norman Personal Firewall Service;c:\program files\Norman\Npf\Bin\npfsvc32.exe [06/04/2009 10:07 597104]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [15/05/2009 12:43 64160]
R0 NDIS_RD;Norman Firewall NDIS driver;c:\windows\system32\drivers\ndis_rd.sys [06/04/2009 10:07 79752]
R1 ISAIONT;ISAIONT;c:\windows\system32\drivers\IsaIoNt.sys [18/10/2005 14:19 3853]
R1 MemMapNt;MemMapNt;c:\windows\system32\drivers\memmapnt.sys [18/10/2005 14:19 3908]
R1 NGS;Norman General Security Driver;c:\program files\Norman\Ngs\Bin\ngs.sys [06/04/2009 10:18 22712]
R1 NPROSEC;Norman Security driver;c:\program files\Norman\Ngs\Bin\nprosec.sys [06/04/2009 10:07 53816]
R1 SMBus;SMBus;c:\windows\system32\drivers\smbus.sys [18/10/2005 14:19 9984]
R1 TDI_RD;Norman Firewall TDI driver;c:\windows\system32\drivers\tdi_rd.sys [06/04/2009 10:07 74624]
R2 Ndiskio;Ndiskio;c:\program files\Norman\Nse\Bin\Ndiskio.sys [06/04/2009 10:07 20448]
R2 NPROSECSVC;Norman Security service;c:\program files\Norman\Ngs\Bin\nprosec.exe [06/04/2009 10:07 121912]
R2 NVOY;Norman Resource Provider;c:\program files\Norman\Npm\Bin\nvoy.exe [06/04/2009 10:07 126008]
R2 SuperMicro Health Assistant;SuperMicro Health Assistant;c:\program files\SUPERMICRO\SDIII\NTService.exe [18/10/2005 14:19 131072]
R2 Supero SD3Service Daemon;Supero SD3Service Daemon;c:\windows\system32\SD3Service.exe [18/10/2005 14:19 40960]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]
R2 Xitami;Xitami Web Server;c:\program files\SUPERMICRO\SDIII\xitami\xiwinnt.exe [18/10/2005 14:19 552960]
R3 NPC;Norman Parental Control;c:\program files\Norman\Npc\Bin\npcsvc32.exe [06/04/2009 10:07 416880]
R3 nsesvc;Norman Scanner Engine Service;c:\program files\Norman\Nse\Bin\Nsesvc.exe [15/05/2009 08:52 310328]
R3 NUAA;Norman User Activity Agent;c:\program files\Norman\Npc\Bin\nuaa.exe [06/04/2009 10:07 121912]
R3 Scheduler;Norman Scheduler Service;c:\program files\Norman\Npm\Bin\scheduler.exe [13/05/2009 10:33 130104]
R3 scsiscan;SCSI Scanner Driver;c:\windows\system32\drivers\scsiscan.sys [30/10/2005 13:42 11520]
S1 superbmc;superbmc;c:\windows\system32\drivers\SUPERBMC.SYS [18/10/2005 14:19 14174]
S2 IPSES;IPSES;c:\windows\System32\svchost.exe -k netsvcs [04/08/2004 13:00 14336]
S2 P32LOAD;Intel® AnyPoint® 3240 USB Modem Firmware Loader;c:\windows\system32\drivers\p31usbld.sys [21/10/2005 19:32 18906]
S3 EPUSBDSK;EPSON USB Mass Storage Driver;c:\windows\system32\drivers\EPUSBDSK.sys [06/12/2005 13:17 29983]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [03/02/2008 15:09 13352]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [19/01/2009 15:35 953168]
S3 NvcMFlt;NvcMFlt;c:\windows\system32\drivers\nvcw32mf.sys [06/04/2009 10:07 19512]
S3 nvcoas;Norman Virus Control on-access component;c:\program files\Norman\nvc\bin\Nvcoas.exe [06/04/2009 10:07 195640]
S3 NVCScheduler;Norman Virus Control Scheduler;"c:\program files\Norman\Npm\Bin\Nvcsched.exe" –> c:\program files\Norman\Npm\Bin\Nvcsched.exe [?]
S3 PRO3200P;Intel® USB ADSL Modem;c:\windows\system32\drivers\p32d2kp.sys [27/04/2002 04:23 530785]
S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);c:\windows\system32\drivers\sea1bus.sys [12/06/2007 18:37 61536]
S3 sea1mdfl;Sony Ericsson Device 0A1 USB WMC Modem Filter;c:\windows\system32\drivers\sea1mdfl.sys [12/06/2007 18:37 9360]
S3 sea1mdm;Sony Ericsson Device 0A1 USB WMC Modem Driver;c:\windows\system32\drivers\sea1mdm.sys [12/06/2007 18:37 97088]
S3 sea1mgmt;Sony Ericsson Device 0A1 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\sea1mgmt.sys [12/06/2007 18:37 88624]
S3 sea1nd5;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (NDIS);c:\windows\system32\drivers\sea1nd5.sys [12/06/2007 18:38 18704]
S3 sea1obex;Sony Ericsson Device 0A1 USB WMC OBEX Interface;c:\windows\system32\drivers\sea1obex.sys [12/06/2007 18:37 86432]
S3 sea1unic;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (WDM);c:\windows\system32\drivers\sea1unic.sys [12/06/2007 18:37 90800]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
IPSES

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2E1A9DE4-ADA0-4501-A46E-6633CDB01654}]
rundll32 magks32.dll,InitO
.
Contents of the 'Scheduled Tasks' folder

2009-05-17 c:\windows\Tasks\Ad-Aware Update (Daily).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-19 11:42]

2009-05-17 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-ATIPTA - c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
HKU-Default-Run-internat - c:\windows\internat.exe
Notify-AtiExtEvent - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://discography.ledzeppelin.com/discography.html
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: Convert link target to Adobe PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - e:\micros~1\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\Norman\npc\bin\nlf.dll
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.co.uk/scan_uk/scan8/oscan8.cab
FF - ProfilePath - c:\documents and settings\Allen Sheena\Application Data\Mozilla\Firefox\Profiles\op6y78jg.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: network.proxy.http - localhost
FF - prefs.js: network.proxy.http_port - 7171
FF - prefs.js: network.proxy.type - 1
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\qfaservices.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-17 18:11
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\Norman\Npm\Bin\elogsvc.exe
c:\program files\Norman\Npm\Bin\Zanda.exe
c:\program files\Norman\Npf\Bin\npfuser.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Teleca Shared\Generic.exe
c:\program files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\WinVNC.exe
c:\program files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
c:\program files\Norman\Npm\Bin\Njeeves.exe
c:\program files\Norman\nvc\bin\Nip.exe
.
**************************************************************************
.
Completion time: 2009-05-17 18:14 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-17 17:13

Pre-Run: 9,013,063,680 bytes free
Post-Run: 9,045,110,784 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

Current=1 Default=1 Failed=3 LastKnownGood=4 Sets=,1,3,4,5,6,7,8,9
235 — E O F — 2009-05-13 07:43
The OTLISTIT2 log.

========== OTLISTIT ==========
Process Explorer.EXE killed successfully!
Process SYS32DLL.exe killed successfully!

Service\Driver perfmons deleted successfully.
File File not found not found.

Service\Driver Print Service deleted successfully.
File File not found not found.

Service\Driver Remote Manager deleted successfully.
File File not found not found.

Service\Driver Indexingbox deleted successfully.
File File not found not found.

Service\Driver NETDown deleted successfully.
File File not found not found.

Service\Driver WindowsKernel deleted successfully.
File File not found not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C7EFE99-C71F-48b8-8CC8-BA506CA76A33}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C7EFE99-C71F-48b8-8CC8-BA506CA76A33}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\pp deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\sysldtray deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\SYS32DLL deleted successfully.
C:\WINDOWS\System32\SYS32DLL.exe moved successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableTaskMgr deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\WINDOWS\system32\pavuppad.exe deleted successfully.
File move failed. C:\WINDOWS\system32\pavuppad.exe scheduled to be moved on reboot.
LoadLibrary failed for C:\WINDOWS\System32\pfxzmtsmtspm.dll
C:\WINDOWS\System32\pfxzmtsmtspm.dll NOT unregistered.
C:\WINDOWS\System32\pfxzmtsmtspm.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\sfxzmtforum.dll
C:\WINDOWS\System32\sfxzmtforum.dll NOT unregistered.
C:\WINDOWS\System32\sfxzmtforum.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\pfxzmtymsg.dll
C:\WINDOWS\System32\pfxzmtymsg.dll NOT unregistered.
C:\WINDOWS\System32\pfxzmtymsg.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\pfxzmticq.dll
C:\WINDOWS\System32\pfxzmticq.dll NOT unregistered.
C:\WINDOWS\System32\pfxzmticq.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\pfxzmtgtal.dll
C:\WINDOWS\System32\pfxzmtgtal.dll NOT unregistered.
C:\WINDOWS\System32\pfxzmtgtal.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\pfxzmtaim.dll
C:\WINDOWS\System32\pfxzmtaim.dll NOT unregistered.
C:\WINDOWS\System32\pfxzmtaim.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\pfxzmtwbmail.dll
C:\WINDOWS\System32\pfxzmtwbmail.dll NOT unregistered.
C:\WINDOWS\System32\pfxzmtwbmail.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\pfxzmtsmt.dll
C:\WINDOWS\System32\pfxzmtsmt.dll NOT unregistered.
C:\WINDOWS\System32\pfxzmtsmt.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\pfxzmtzpurse.dll
C:\WINDOWS\System32\pfxzmtzpurse.dll NOT unregistered.
C:\WINDOWS\System32\pfxzmtzpurse.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\pfxzmtrpurse.dll
C:\WINDOWS\System32\pfxzmtrpurse.dll NOT unregistered.
C:\WINDOWS\System32\pfxzmtrpurse.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\pfxzmtfpurse.dll
C:\WINDOWS\System32\pfxzmtfpurse.dll NOT unregistered.
C:\WINDOWS\System32\pfxzmtfpurse.dll moved successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
File\Folder C:\WINDOWS\system32\SYS32DLL.exe not found.
C:\WINDOWS\System32\CF20455.exe moved successfully.
C:\WINDOWS\System32\CF19610.exe moved successfully.
C:\WINDOWS\t55ft2692f44.dat moved successfully.
C:\WINDOWS\9g2234wesdf3dfgjf23 moved successfully.
C:\WINDOWS\System32\218538 moved successfully.
Folder move failed. C:\WINDOWS\System32\bookls scheduled to be moved on reboot.
C:\WINDOWS\internat.exe moved successfully.
C:\WINDOWS\System32\inform.dat moved successfully.
C:\WINDOWS\System32\pmx moved successfully.
C:\WINDOWS\System32\mywebhit.ini moved successfully.
C:\WINDOWS\imsins.BAK moved successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\nvcbin.def.fa1b0d9b.tmp scheduled to be deleted on reboot.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTListIt2 by OldTimer - Version 2.0.15.8 log created on 05172009_091909

Files moved on Reboot…
File move failed. C:\WINDOWS\system32\pavuppad.exe scheduled to be moved on reboot.
Folder move failed. C:\WINDOWS\System32\bookls scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\nvcbin.def.fa1b0d9b.tmp scheduled to be moved on reboot.

Registry entries deleted on Reboot…

The Hijackthis log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:21:06, on 17/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Norman\Npm\Bin\Elogsvc.exe
C:\Program Files\Norman\Ngs\Bin\Nprosec.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norman\Npm\Bin\Zanda.exe
C:\Program Files\Norman\npm\bin\nvoy.exe
C:\Program Files\Norman\npf\bin\npfsvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norman\npf\bin\npfuser.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\INTEL\DSLSetup\ProDsl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Norman\Npm\Bin\ZLH.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
F:\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SUPERMICRO\SDIII\NTService.exe
C:\WINDOWS\system32\SD3Service.exe
C:\WINDOWS\system32\WinVNC.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\SUPERMICRO\SDIII\Xitami\xiwinnt.exe
C:\Program Files\Norman\Npm\Bin\scheduler.exe
C:\Program Files\Norman\Npm\Bin\Njeeves.exe
C:\Program Files\Norman\npc\bin\npcsvc32.exe
C:\Program Files\Norman\npc\bin\nuaa.exe
C:\Program Files\Norman\Nvc\Bin\Nip.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\notepad.exe
F:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://discography.ledzeppelin.com/discography.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\pavuppad.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DSL Connection Manager] C:\Program Files\INTEL\DSLSetup\ProDsl.exe
O4 - HKLM\..\Run: [AWMON] "F:\Norman Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo R800] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9YE.EXE /P23 "EPSON Stylus Photo R800" /O6 "USB002" /M "Stylus Photo R800"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "F:\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Norman ZANDA] "C:\Program Files\Norman\Npm\Bin\ZLH.EXE" /LOAD /SPLASH
O4 - HKLM\..\Run: [NPCTray] C:\Program Files\Norman\npc\bin\npc_tray.exe /LOAD
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = F:\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Supero Doctor III Client.lnk = C:\Program Files\SUPERMICRO\SDIII\SuperoDoctor.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\norman\npc\bin\nlf.dll
O10 - Unknown file in Winsock LSP: c:\program files\norman\npc\bin\nlf.dll
O10 - Unknown file in Winsock LSP: c:\program files\norman\npc\bin\nlf.dll
O10 - Unknown file in Winsock LSP: c:\program files\norman\npc\bin\nlf.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.co.uk/scan_uk/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1230734870593
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1230734831031
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe (file missing)
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - Unknown owner - C:\WINDOWS\ATKKBService.exe (file missing)
O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:\Program Files\Norman\Npm\Bin\Elogsvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Norman NJeeves - Norman ASA - C:\Program Files\Norman\Npm\Bin\Njeeves.exe
O23 - Service: Norman ZANDA - Norman ASA - C:\Program Files\Norman\Npm\Bin\Zanda.exe
O23 - Service: Norman Parental Control (NPC) - Norman ASA - C:\Program Files\Norman\npc\bin\npcsvc32.exe
O23 - Service: Norman Personal Firewall Service (NPFSvc32) - Norman ASA - C:\Program Files\Norman\npf\bin\npfsvc32.exe
O23 - Service: Norman Security service (NPROSECSVC) - Norman ASA - C:\Program Files\Norman\Ngs\Bin\Nprosec.exe
O23 - Service: Norman Scanner Engine Service (nsesvc) - Norman ASA - C:\Program Files\Norman\nse\bin\NSESVC.EXE
O23 - Service: Norman User Activity Agent (NUAA) - Norman ASA - C:\Program Files\Norman\npc\bin\nuaa.exe
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Program Files\Norman\Nvc\Bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Unknown owner - C:\Program Files\Norman\Npm\Bin\Nvcsched.exe (file missing)
O23 - Service: Norman Resource Provider (NVOY) - Norman ASA - C:\Program Files\Norman\npm\bin\nvoy.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - F:\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - F:\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe (file missing)
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB - Unknown owner - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe (file missing)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe (file missing)
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Norman Scheduler Service (Scheduler) - Norman ASA - C:\Program Files\Norman\Npm\Bin\scheduler.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: SuperMicro Health Assistant - Unknown owner - C:\Program Files\SUPERMICRO\SDIII\NTService.exe
O23 - Service: Supero SD3Service Daemon - Unknown owner - C:\WINDOWS\system32\SD3Service.exe
O23 - Service: TridiaVNC Server (winvnc) - Tridia Corporation - C:\WINDOWS\system32\WinVNC.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
O23 - Service: Xitami Web Server (Xitami) - Unknown owner - C:\Program Files\SUPERMICRO\SDIII\Xitami\xiwinnt.exe

–
End of file - 14241 bytes

I look forward to your response.

Many thanks.
Hi ADS,

Open hijackthis, do a system scan only and checkmark these lines, if present

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\pavuppad.exe,


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.


We will use combofix again but run it differently.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE
Do Not copy the word CODE

File::
C:\WINDOWS\system32\pavuppad.exe

DirLook::
c:\windows\system32\bookls

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2E1A9DE4-ADA0-4501-A46E-6633CDB01654}]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"EnableProfileQuota"=-

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]




Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Please post back
  • combofix log
  • MBAM log
  • new HJT log

How's the computer?
Thanks
The ComboFix Log.

ComboFix 09-05-17.01 - Allen Sheena 17/05/2009 21:21.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1022.522 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Allen Sheena\Desktop\CFScript.txt
AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: Norman Security Suite *On-access scanning disabled* (Updated) {EB9EFB40-AE72-4C43-B204-0FCD0E92D5F1}
FW: Norman Security Suite *disabled* {83B29CE9-9DE2-2CB5-9AB3-780D70FF12B0}
* Created a new restore point

FILE ::
c:\windows\system32\pavuppad.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\mfc70.dll

.
((((((((((((((((((((((((( Files Created from 2009-04-17 to 2009-05-17 )))))))))))))))))))))))))))))))
.

2009-05-15 20:44 . 2009-05-15 20:44 ——– d—–w C:\_OTListIt
2009-05-15 12:00 . 2009-05-15 11:42 15688 —-a-w c:\windows\system32\lsdelete.exe
2009-05-15 11:43 . 2009-05-15 11:42 64160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-05-15 11:39 . 2009-05-15 11:39 ——– dc-h–w c:\documents and settings\All Users\Application Data\{2BAE6915-8510-4B9F-B498-02DA86258AA0}
2009-05-15 11:39 . 2009-05-15 11:39 ——– d—–w c:\program files\Lavasoft
2009-05-15 11:39 . 2009-05-15 11:39 ——– d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2009-05-12 23:09 . 2009-05-17 20:26 ——– d-sh–w c:\windows\system32\bookls

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-17 20:05 . 2009-04-06 09:06 ——– d—–w c:\program files\Norman
2009-05-17 17:03 . 2009-03-07 00:21 ——– d—–w c:\program files\Common
2009-04-14 08:12 . 2005-10-21 00:05 ——– d—–w c:\program files\Common Files\Adobe
2009-03-07 01:07 . 2009-03-07 01:07 81 —-a-w C:\CTX.DAT
2009-03-06 14:22 . 2004-08-04 12:00 284160 —-a-w c:\windows\system32\pdh.dll
2009-02-27 11:12 . 2007-11-04 02:30 173473 —-a-w c:\windows\system32\mssock.dat
2009-02-20 08:10 . 2004-08-04 12:00 666112 —-a-w c:\windows\system32\wininet.dll
2009-02-20 08:10 . 2004-08-04 12:00 81920 —-a-w c:\windows\system32\ieencode.dll
2009-04-04 12:22 . 2008-04-24 18:36 67688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2009-04-04 12:22 . 2008-04-24 18:36 54368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2009-04-04 12:22 . 2008-04-24 18:36 34944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2009-04-04 12:22 . 2008-04-24 18:36 46712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2009-04-04 12:22 . 2008-04-24 18:36 172136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\windows\system32\bookls —-

2009-05-12 23:09 . 2009-05-17 20:04 0 —-a-w c:\windows\system32\bookls\dooi.poc
2009-05-12 23:09 . 2009-05-17 20:15 83063 —-a-w c:\windows\system32\bookls\orde.poc


((((((((((((((((((((((((((((( SnapShot@2009-05-17_17.11.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-18 13:11 . 2009-05-17 20:05 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2005-10-18 13:11 . 2009-05-17 17:09 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2005-10-18 13:11 . 2009-05-17 20:05 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2005-10-18 13:11 . 2009-05-17 17:09 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2005-10-18 13:11 . 2009-05-17 20:05 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2005-10-18 13:11 . 2009-05-17 17:09 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-21 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
"DSL Connection Manager"="c:\program files\INTEL\DSLSetup\ProDsl.exe" [2007-10-22 65536]
"AWMON"="f:\norman ad-aware se professional\Ad-Watch.exe" [2004-09-21 538112]
"EPSON Stylus Photo R800"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9YE.EXE" [2005-01-13 98304]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-24 185896]
"Acrobat Assistant 7.0"="f:\adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-01-26 495616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"Norman ZANDA"="c:\program files\Norman\Npm\Bin\ZLH.EXE" [2009-02-11 187504]
"NPCTray"="c:\program files\Norman\npc\bin\npc_tray.exe" [2007-09-17 126008]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [BU]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-04-15 77824]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-22 1622016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2008-8-6 25214]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-10-25 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
InterVideo WinCinema Manager.lnk - f:\intervideo\Common\Bin\WinCinemaMgr.exe [2005-10-25 106496]
Supero Doctor III Client.lnk - c:\program files\SUPERMICRO\SDIII\SuperoDoctor.exe [2005-10-18 397312]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,c:\windows\system32\pavuppad.exe,"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll
"wave2"= serwvdrv.dll
"wave3"= serwvdrv.dll
"wave4"= serwvdrv.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"f:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=

P2 NPFSvc32;Norman Personal Firewall Service;c:\program files\Norman\Npf\Bin\npfsvc32.exe [06/04/2009 10:07 597104]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [15/05/2009 12:43 64160]
R0 NDIS_RD;Norman Firewall NDIS driver;c:\windows\system32\drivers\ndis_rd.sys [06/04/2009 10:07 79752]
R1 ISAIONT;ISAIONT;c:\windows\system32\drivers\IsaIoNt.sys [18/10/2005 14:19 3853]
R1 MemMapNt;MemMapNt;c:\windows\system32\drivers\memmapnt.sys [18/10/2005 14:19 3908]
R1 NGS;Norman General Security Driver;c:\program files\Norman\Ngs\Bin\ngs.sys [06/04/2009 10:18 22712]
R1 NPROSEC;Norman Security driver;c:\program files\Norman\Ngs\Bin\nprosec.sys [06/04/2009 10:07 53816]
R1 SMBus;SMBus;c:\windows\system32\drivers\smbus.sys [18/10/2005 14:19 9984]
R1 TDI_RD;Norman Firewall TDI driver;c:\windows\system32\drivers\tdi_rd.sys [06/04/2009 10:07 74624]
R2 Ndiskio;Ndiskio;c:\program files\Norman\Nse\Bin\Ndiskio.sys [06/04/2009 10:07 20448]
R2 NPROSECSVC;Norman Security service;c:\program files\Norman\Ngs\Bin\nprosec.exe [06/04/2009 10:07 121912]
R2 NVOY;Norman Resource Provider;c:\program files\Norman\Npm\Bin\nvoy.exe [06/04/2009 10:07 126008]
R2 SuperMicro Health Assistant;SuperMicro Health Assistant;c:\program files\SUPERMICRO\SDIII\NTService.exe [18/10/2005 14:19 131072]
R2 Supero SD3Service Daemon;Supero SD3Service Daemon;c:\windows\system32\SD3Service.exe [18/10/2005 14:19 40960]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]
R2 Xitami;Xitami Web Server;c:\program files\SUPERMICRO\SDIII\xitami\xiwinnt.exe [18/10/2005 14:19 552960]
R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [19/01/2009 15:35 953168]
R3 NPC;Norman Parental Control;c:\program files\Norman\Npc\Bin\npcsvc32.exe [06/04/2009 10:07 416880]
R3 nsesvc;Norman Scanner Engine Service;c:\program files\Norman\Nse\Bin\Nsesvc.exe [15/05/2009 08:52 310328]
R3 NUAA;Norman User Activity Agent;c:\program files\Norman\Npc\Bin\nuaa.exe [06/04/2009 10:07 121912]
R3 Scheduler;Norman Scheduler Service;c:\program files\Norman\Npm\Bin\scheduler.exe [13/05/2009 10:33 130104]
R3 scsiscan;SCSI Scanner Driver;c:\windows\system32\drivers\scsiscan.sys [30/10/2005 13:42 11520]
S1 superbmc;superbmc;c:\windows\system32\drivers\SUPERBMC.SYS [18/10/2005 14:19 14174]
S2 IPSES;IPSES;c:\windows\System32\svchost.exe -k netsvcs [04/08/2004 13:00 14336]
S2 P32LOAD;Intel® AnyPoint® 3240 USB Modem Firmware Loader;c:\windows\system32\drivers\p31usbld.sys [21/10/2005 19:32 18906]
S3 EPUSBDSK;EPSON USB Mass Storage Driver;c:\windows\system32\drivers\EPUSBDSK.sys [06/12/2005 13:17 29983]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [03/02/2008 15:09 13352]
S3 NvcMFlt;NvcMFlt;c:\windows\system32\drivers\nvcw32mf.sys [06/04/2009 10:07 19512]
S3 nvcoas;Norman Virus Control on-access component;c:\program files\Norman\nvc\bin\Nvcoas.exe [06/04/2009 10:07 195640]
S3 NVCScheduler;Norman Virus Control Scheduler;"c:\program files\Norman\Npm\Bin\Nvcsched.exe" –> c:\program files\Norman\Npm\Bin\Nvcsched.exe [?]
S3 PRO3200P;Intel® USB ADSL Modem;c:\windows\system32\drivers\p32d2kp.sys [27/04/2002 04:23 530785]
S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);c:\windows\system32\drivers\sea1bus.sys [12/06/2007 18:37 61536]
S3 sea1mdfl;Sony Ericsson Device 0A1 USB WMC Modem Filter;c:\windows\system32\drivers\sea1mdfl.sys [12/06/2007 18:37 9360]
S3 sea1mdm;Sony Ericsson Device 0A1 USB WMC Modem Driver;c:\windows\system32\drivers\sea1mdm.sys [12/06/2007 18:37 97088]
S3 sea1mgmt;Sony Ericsson Device 0A1 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\sea1mgmt.sys [12/06/2007 18:37 88624]
S3 sea1nd5;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (NDIS);c:\windows\system32\drivers\sea1nd5.sys [12/06/2007 18:38 18704]
S3 sea1obex;Sony Ericsson Device 0A1 USB WMC OBEX Interface;c:\windows\system32\drivers\sea1obex.sys [12/06/2007 18:37 86432]
S3 sea1unic;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (WDM);c:\windows\system32\drivers\sea1unic.sys [12/06/2007 18:37 90800]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
IPSES
.
Contents of the 'Scheduled Tasks' folder

2009-05-17 c:\windows\Tasks\Ad-Aware Update (Daily).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-19 11:42]

2009-05-17 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://discography.ledzeppelin.com/discography.html
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
IE: Convert link target to Adobe PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - e:\micros~1\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\Norman\npc\bin\nlf.dll
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.co.uk/scan_uk/scan8/oscan8.cab
FF - ProfilePath - c:\documents and settings\Allen Sheena\Application Data\Mozilla\Firefox\Profiles\op6y78jg.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: network.proxy.http - localhost
FF - prefs.js: network.proxy.http_port - 7171
FF - prefs.js: network.proxy.type - 1
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\qfaservices.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-17 21:25
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\system32\pavuppad.exe 343040 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
Completion time: 2009-05-17 21:28
ComboFix-quarantined-files.txt 2009-05-17 20:28
ComboFix2.txt 2009-05-17 17:14

Pre-Run: 9,019,293,696 bytes free
Post-Run: 9,011,482,624 bytes free

Current=1 Default=1 Failed=3 LastKnownGood=4 Sets=,1,3,4,5,6,7,8,9
203 — E O F — 2009-05-13 07:43

The Malware log.

Malwarebytes' Anti-Malware 1.36
Database version: 2145
Windows 5.1.2600 Service Pack 3

17/05/2009 21:38:13
mbam-log-2009-05-17 (21-38-13).txt

Scan type: Quick Scan
Objects scanned: 91583
Time elapsed: 3 minute(s), 12 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 1
Registry Data Items Infected: 4
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\fe345.fe345mgr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\fe345.fe345mgr.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\main.bho.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5e5efa8f-9f53-418e-b78e-44866667a404} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7c7efe99-c71f-48b8-8cc8-ba506ca76a33} (Password.Stealer) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\pavuppad.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\pavuppad.exe,) Good: (userinit.exe) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\pavuppad.exe (Trojan.Agent) -> Quarantined and deleted successfully.
The HijackThis log.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:46:30, on 17/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Norman\Npm\Bin\Elogsvc.exe
C:\Program Files\Norman\Ngs\Bin\Nprosec.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norman\Npm\Bin\Zanda.exe
C:\Program Files\Norman\npm\bin\nvoy.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Norman\npf\bin\npfsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\INTEL\DSLSetup\ProDsl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Norman\Npm\Bin\ZLH.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
F:\Adobe\Acrobat 7.0\Acrobat\Acrobat_sl.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
F:\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SUPERMICRO\SDIII\NTService.exe
C:\WINDOWS\system32\SD3Service.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\WinVNC.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\SUPERMICRO\SDIII\Xitami\xiwinnt.exe
C:\Program Files\Norman\npf\bin\npfuser.exe
C:\Program Files\Norman\Npm\Bin\scheduler.exe
C:\Program Files\Norman\Npm\Bin\Njeeves.exe
C:\Program Files\Norman\npc\bin\npcsvc32.exe
C:\Program Files\Norman\nse\bin\NSESVC.EXE
C:\Program Files\Norman\npc\bin\nuaa.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Norman\Nvc\Bin\Nip.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://discography.ledzeppelin.com/discography.html
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DSL Connection Manager] C:\Program Files\INTEL\DSLSetup\ProDsl.exe
O4 - HKLM\..\Run: [AWMON] "F:\Norman Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo R800] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9YE.EXE /P23 "EPSON Stylus Photo R800" /O6 "USB002" /M "Stylus Photo R800"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "F:\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Norman ZANDA] "C:\Program Files\Norman\Npm\Bin\ZLH.EXE" /LOAD /SPLASH
O4 - HKLM\..\Run: [NPCTray] C:\Program Files\Norman\npc\bin\npc_tray.exe /LOAD
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = F:\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Supero Doctor III Client.lnk = C:\Program Files\SUPERMICRO\SDIII\SuperoDoctor.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://F:\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\norman\npc\bin\nlf.dll
O10 - Unknown file in Winsock LSP: c:\program files\norman\npc\bin\nlf.dll
O10 - Unknown file in Winsock LSP: c:\program files\norman\npc\bin\nlf.dll
O10 - Unknown file in Winsock LSP: c:\program files\norman\npc\bin\nlf.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.co.uk/scan_uk/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1230734870593
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1230734831031
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe (file missing)
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - Unknown owner - C:\WINDOWS\ATKKBService.exe (file missing)
O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:\Program Files\Norman\Npm\Bin\Elogsvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Norman NJeeves - Norman ASA - C:\Program Files\Norman\Npm\Bin\Njeeves.exe
O23 - Service: Norman ZANDA - Norman ASA - C:\Program Files\Norman\Npm\Bin\Zanda.exe
O23 - Service: Norman Parental Control (NPC) - Norman ASA - C:\Program Files\Norman\npc\bin\npcsvc32.exe
O23 - Service: Norman Personal Firewall Service (NPFSvc32) - Norman ASA - C:\Program Files\Norman\npf\bin\npfsvc32.exe
O23 - Service: Norman Security service (NPROSECSVC) - Norman ASA - C:\Program Files\Norman\Ngs\Bin\Nprosec.exe
O23 - Service: Norman Scanner Engine Service (nsesvc) - Norman ASA - C:\Program Files\Norman\nse\bin\NSESVC.EXE
O23 - Service: Norman User Activity Agent (NUAA) - Norman ASA - C:\Program Files\Norman\npc\bin\nuaa.exe
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Program Files\Norman\Nvc\Bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Unknown owner - C:\Program Files\Norman\Npm\Bin\Nvcsched.exe (file missing)
O23 - Service: Norman Resource Provider (NVOY) - Norman ASA - C:\Program Files\Norman\npm\bin\nvoy.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - F:\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - F:\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe (file missing)
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB - Unknown owner - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe (file missing)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe (file missing)
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Norman Scheduler Service (Scheduler) - Norman ASA - C:\Program Files\Norman\Npm\Bin\scheduler.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: SuperMicro Health Assistant - Unknown owner - C:\Program Files\SUPERMICRO\SDIII\NTService.exe
O23 - Service: Supero SD3Service Daemon - Unknown owner - C:\WINDOWS\system32\SD3Service.exe
O23 - Service: TridiaVNC Server (winvnc) - Tridia Corporation - C:\WINDOWS\system32\WinVNC.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
O23 - Service: Xitami Web Server (Xitami) - Unknown owner - C:\Program Files\SUPERMICRO\SDIII\Xitami\xiwinnt.exe

–
End of file - 14526 bytes


The computer seems to work fine. What is my health status?

Once again, my thanks.
Hi

It certainly looks a lot better now.

Let's see if combofix can remove that folder. We will use another CFScript

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE
Do Not copy the word CODE

KillAll::

Folder::
c:\windows\system32\bookls
In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]




Please download RootRepeal to your desktop
  • Physically disconnect your machine from the internet as your system will be unprotected.
  • Unzip it to it's own folder, close all other programs especially your security programs (anti-spyware, anti-virus, and firewall) and run RootRepeal.exe
  • Click the Report tab at the bottom and then the Scan button.
  • A box will pop up, check the boxes beside Drivers, Files, Processes SSDT and click OK.
  • Another box will open, check the boxes beside all the drives, eg : C:\, then click OK.
  • The scan will take a little while to run, so let it go unhindered.
  • Once it is done, click the Save Report button, call it RepealScan and save the log to your desktop.
  • Reconnect to the internet.
  • Post the log here in your reply.

Next

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    Do not copy the word CODE note the script starts with the :

    :regfind
    proquota.exe
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Please post back with
  • combofix log
  • RootRepeal log
  • SystemLook log

Thanks
When I reboot after using ComboFix I get quite a few this will change your Registry notices. I am not sure whether to accept or block these requests. I am very cautious when it comes to changing the registry. What should I do? Thanks.
The Combofix log.

ComboFix 09-05-17.04 - Allen Sheena 18/05/2009 9:16.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1022.519 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Allen Sheena\Desktop\CFScript.txt
AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: Norman Security Suite *On-access scanning disabled* (Updated) {EB9EFB40-AE72-4C43-B204-0FCD0E92D5F1}
FW: Norman Security Suite *disabled* {83B29CE9-9DE2-2CB5-9AB3-780D70FF12B0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\bookls
c:\windows\system32\bookls\dooi.poc
c:\windows\system32\bookls\orde.poc

.
((((((((((((((((((((((((( Files Created from 2009-04-18 to 2009-05-18 )))))))))))))))))))))))))))))))
.

2009-05-17 20:33 . 2009-05-17 20:33 ——– d—–w c:\documents and settings\Allen Sheena\Application Data\Malwarebytes
2009-05-17 20:33 . 2009-04-06 14:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-17 20:33 . 2009-04-06 14:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-17 20:33 . 2009-05-17 20:33 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-15 20:44 . 2009-05-15 20:44 ——– d—–w C:\_OTListIt
2009-05-15 12:00 . 2009-05-15 11:42 15688 —-a-w c:\windows\system32\lsdelete.exe
2009-05-15 11:43 . 2009-05-15 11:42 64160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-05-15 11:39 . 2009-05-15 11:39 ——– dc-h–w c:\documents and settings\All Users\Application Data\{2BAE6915-8510-4B9F-B498-02DA86258AA0}
2009-05-15 11:39 . 2009-05-15 11:39 ——– d—–w c:\program files\Lavasoft
2009-05-15 11:39 . 2009-05-15 11:39 ——– d—–w c:\documents and settings\All Users\Application Data\Lavasoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-18 08:19 . 2009-04-06 09:06 ——– d—–w c:\program files\Norman
2009-05-17 17:03 . 2009-03-07 00:21 ——– d—–w c:\program files\Common
2009-04-14 08:12 . 2005-10-21 00:05 ——– d—–w c:\program files\Common Files\Adobe
2009-03-07 01:07 . 2009-03-07 01:07 81 —-a-w C:\CTX.DAT
2009-03-06 14:22 . 2004-08-04 12:00 284160 —-a-w c:\windows\system32\pdh.dll
2009-02-27 11:12 . 2007-11-04 02:30 173473 —-a-w c:\windows\system32\mssock.dat
2009-02-20 08:10 . 2004-08-04 12:00 666112 —-a-w c:\windows\system32\wininet.dll
2009-02-20 08:10 . 2004-08-04 12:00 81920 —-a-w c:\windows\system32\ieencode.dll
2009-04-04 12:22 . 2008-04-24 18:36 67688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2009-04-04 12:22 . 2008-04-24 18:36 54368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2009-04-04 12:22 . 2008-04-24 18:36 34944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2009-04-04 12:22 . 2008-04-24 18:36 46712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2009-04-04 12:22 . 2008-04-24 18:36 172136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-05-17_17.11.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-18 08:21 . 2009-05-18 08:21 16384 c:\windows\temp\Perflib_Perfdata_b50.dat
+ 2005-10-18 13:11 . 2009-05-17 20:05 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2005-10-18 13:11 . 2009-05-17 17:09 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2005-10-18 13:11 . 2009-05-17 20:05 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2005-10-18 13:11 . 2009-05-17 17:09 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2005-10-18 13:11 . 2009-05-17 20:05 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2005-10-18 13:11 . 2009-05-17 17:09 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-21 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
"DSL Connection Manager"="c:\program files\INTEL\DSLSetup\ProDsl.exe" [2007-10-22 65536]
"AWMON"="f:\norman ad-aware se professional\Ad-Watch.exe" [2004-09-21 538112]
"EPSON Stylus Photo R800"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9YE.EXE" [2005-01-13 98304]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-24 185896]
"Acrobat Assistant 7.0"="f:\adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-01-26 495616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"Norman ZANDA"="c:\program files\Norman\Npm\Bin\ZLH.EXE" [2009-02-11 187504]
"NPCTray"="c:\program files\Norman\npc\bin\npc_tray.exe" [2007-09-17 126008]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [BU]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-04-15 77824]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-22 1622016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2008-8-6 25214]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-10-25 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
InterVideo WinCinema Manager.lnk - f:\intervideo\Common\Bin\WinCinemaMgr.exe [2005-10-25 106496]
Supero Doctor III Client.lnk - c:\program files\SUPERMICRO\SDIII\SuperoDoctor.exe [2005-10-18 397312]

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll
"wave2"= serwvdrv.dll
"wave3"= serwvdrv.dll
"wave4"= serwvdrv.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"f:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=

P2 NPFSvc32;Norman Personal Firewall Service;c:\program files\Norman\Npf\Bin\npfsvc32.exe [06/04/2009 10:07 597104]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [15/05/2009 12:43 64160]
R0 NDIS_RD;Norman Firewall NDIS driver;c:\windows\system32\drivers\ndis_rd.sys [06/04/2009 10:07 79752]
R1 ISAIONT;ISAIONT;c:\windows\system32\drivers\IsaIoNt.sys [18/10/2005 14:19 3853]
R1 MemMapNt;MemMapNt;c:\windows\system32\drivers\memmapnt.sys [18/10/2005 14:19 3908]
R1 NGS;Norman General Security Driver;c:\program files\Norman\Ngs\Bin\ngs.sys [06/04/2009 10:18 22712]
R1 NPROSEC;Norman Security driver;c:\program files\Norman\Ngs\Bin\nprosec.sys [06/04/2009 10:07 53816]
R1 SMBus;SMBus;c:\windows\system32\drivers\smbus.sys [18/10/2005 14:19 9984]
R1 TDI_RD;Norman Firewall TDI driver;c:\windows\system32\drivers\tdi_rd.sys [06/04/2009 10:07 74624]
R2 Ndiskio;Ndiskio;c:\program files\Norman\Nse\Bin\Ndiskio.sys [06/04/2009 10:07 20448]
R2 NPROSECSVC;Norman Security service;c:\program files\Norman\Ngs\Bin\nprosec.exe [06/04/2009 10:07 121912]
R2 NVOY;Norman Resource Provider;c:\program files\Norman\Npm\Bin\nvoy.exe [06/04/2009 10:07 126008]
R2 SuperMicro Health Assistant;SuperMicro Health Assistant;c:\program files\SUPERMICRO\SDIII\NTService.exe [18/10/2005 14:19 131072]
R2 Supero SD3Service Daemon;Supero SD3Service Daemon;c:\windows\system32\SD3Service.exe [18/10/2005 14:19 40960]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]
R2 Xitami;Xitami Web Server;c:\program files\SUPERMICRO\SDIII\xitami\xiwinnt.exe [18/10/2005 14:19 552960]
R3 NPC;Norman Parental Control;c:\program files\Norman\Npc\Bin\npcsvc32.exe [06/04/2009 10:07 416880]
R3 nsesvc;Norman Scanner Engine Service;c:\program files\Norman\Nse\Bin\Nsesvc.exe [15/05/2009 08:52 310328]
R3 NUAA;Norman User Activity Agent;c:\program files\Norman\Npc\Bin\nuaa.exe [06/04/2009 10:07 121912]
R3 Scheduler;Norman Scheduler Service;c:\program files\Norman\Npm\Bin\scheduler.exe [13/05/2009 10:33 130104]
R3 scsiscan;SCSI Scanner Driver;c:\windows\system32\drivers\scsiscan.sys [30/10/2005 13:42 11520]
S1 superbmc;superbmc;c:\windows\system32\drivers\SUPERBMC.SYS [18/10/2005 14:19 14174]
S2 IPSES;IPSES;c:\windows\System32\svchost.exe -k netsvcs [04/08/2004 13:00 14336]
S2 P32LOAD;Intel® AnyPoint® 3240 USB Modem Firmware Loader;c:\windows\system32\drivers\p31usbld.sys [21/10/2005 19:32 18906]
S3 EPUSBDSK;EPSON USB Mass Storage Driver;c:\windows\system32\drivers\EPUSBDSK.sys [06/12/2005 13:17 29983]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [03/02/2008 15:09 13352]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [19/01/2009 15:35 953168]
S3 NvcMFlt;NvcMFlt;c:\windows\system32\drivers\nvcw32mf.sys [06/04/2009 10:07 19512]
S3 nvcoas;Norman Virus Control on-access component;c:\program files\Norman\nvc\bin\Nvcoas.exe [06/04/2009 10:07 195640]
S3 NVCScheduler;Norman Virus Control Scheduler;"c:\program files\Norman\Npm\Bin\Nvcsched.exe" –> c:\program files\Norman\Npm\Bin\Nvcsched.exe [?]
S3 PRO3200P;Intel® USB ADSL Modem;c:\windows\system32\drivers\p32d2kp.sys [27/04/2002 04:23 530785]
S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);c:\windows\system32\drivers\sea1bus.sys [12/06/2007 18:37 61536]
S3 sea1mdfl;Sony Ericsson Device 0A1 USB WMC Modem Filter;c:\windows\system32\drivers\sea1mdfl.sys [12/06/2007 18:37 9360]
S3 sea1mdm;Sony Ericsson Device 0A1 USB WMC Modem Driver;c:\windows\system32\drivers\sea1mdm.sys [12/06/2007 18:37 97088]
S3 sea1mgmt;Sony Ericsson Device 0A1 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\sea1mgmt.sys [12/06/2007 18:37 88624]
S3 sea1nd5;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (NDIS);c:\windows\system32\drivers\sea1nd5.sys [12/06/2007 18:38 18704]
S3 sea1obex;Sony Ericsson Device 0A1 USB WMC OBEX Interface;c:\windows\system32\drivers\sea1obex.sys [12/06/2007 18:37 86432]
S3 sea1unic;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (WDM);c:\windows\system32\drivers\sea1unic.sys [12/06/2007 18:37 90800]

— Other Services/Drivers In Memory —

*Deregistered* - mchInjDrv

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
IPSES
.
Contents of the 'Scheduled Tasks' folder

2009-05-17 c:\windows\Tasks\Ad-Aware Update (Daily).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-19 11:42]

2009-05-18 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://discography.ledzeppelin.com/discography.html
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: Convert link target to Adobe PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - f:\adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - e:\micros~1\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\Norman\npc\bin\nlf.dll
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.co.uk/scan_uk/scan8/oscan8.cab
FF - ProfilePath - c:\documents and settings\Allen Sheena\Application Data\Mozilla\Firefox\Profiles\op6y78jg.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: network.proxy.http - localhost
FF - prefs.js: network.proxy.http_port - 7171
FF - prefs.js: network.proxy.type - 1
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\qfaservices.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-18 09:20
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3512)
c:\program files\Norman\nvc\bin\Niphk.dll
.
———————— Other Running Processes ————————
.
c:\program files\Norman\Npm\Bin\elogsvc.exe
c:\program files\Norman\Npm\Bin\Zanda.exe
c:\program files\Norman\Npf\Bin\npfuser.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
f:\adobe\Acrobat 7.0\Acrobat\Acrobat_sl.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Teleca Shared\Generic.exe
c:\program files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\WinVNC.exe
c:\program files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
c:\program files\Norman\Npm\Bin\Njeeves.exe
c:\program files\Norman\nvc\bin\Nip.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-05-18 9:24 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-18 08:24
ComboFix2.txt 2009-05-17 20:28
ComboFix3.txt 2009-05-17 17:14

Pre-Run: 8,978,522,112 bytes free
Post-Run: 9,002,311,680 bytes free

Current=1 Default=1 Failed=3 LastKnownGood=4 Sets=,1,3,4,5,6,7,8,9
226 — E O F — 2009-05-13 07:43


More to follow.
The Root Repeal Log ROOTREPEAL © AD, 2007-2008 ================================================== Scan Time: 2009/05/18 09:32 Program Version: Version 1.2.3.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: catchme.sys Image Path: C:\DOCUME~1\ALLENS~1\LOCALS~1\Temp\catchme.sys Address: 0xF77B8000 Size: 31744 File Visible: No Status: - Name: Combo-Fix.sys Image Path: Combo-Fix.sys Address: 0xF7510000 Size: 60416 File Visible: No Status: - Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xF3838000 Size: 98304 File Visible: No Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF79D6000 Size: 8192 File Visible: No Status: - Name: PROCEXP90.SYS Image Path: C:\WINDOWS\system32\Drivers\PROCEXP90.SYS Address: 0xF7A50000 Size: 6464 File Visible: No Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xB7E42000 Size: 45056 File Visible: No Status: - Hidden/Locked Files ——————- Path: C:\Program Files\SUPERMICRO\SDIII\xitami\logs\console.log Status: Allocation size mismatch (API: 344, Raw: 0) Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\32\560-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v32-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v560-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\01\10-{351497A7-6E40-3164-EBA3-CA9837145F7D}-v1-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v10-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\11\541-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v11-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v541-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\12\544-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v12-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v544-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\13\542-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v13-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v542-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\14\543-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v14-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v543-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\15\549-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v15-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v549-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\16\545-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v16-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v545-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\17\546-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v17-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v546-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\18\547-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v18-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v547-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\19\548-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v19-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v548-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\20\553-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v20-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v553-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\21\550-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v21-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v550-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\22\551-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v22-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v551-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\23\552-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v23-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v552-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\24\554-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v24-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v554-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\25\555-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v25-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v555-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\26\593-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v26-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v593-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\27\556-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v27-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v556-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\28\564-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v28-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v564-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\29\557-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v29-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v557-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\30\558-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v30-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v558-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\31\559-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v31-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v559-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\33\561-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v33-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v561-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\34\562-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v34-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v562-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\35\563-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v35-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v563-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\36\572-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v36-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v572-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\37\565-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v37-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v565-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\38\566-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v38-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v566-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\39\567-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v39-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v567-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\40\568-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v40-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v568-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\41\569-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v41-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v569-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\42\570-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v42-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v570-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\43\571-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v43-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v571-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\44\590-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v44-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v590-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\45\573-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v45-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v573-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\46\574-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v46-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v574-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\47\575-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v47-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v575-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\48\576-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v48-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v576-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\49\577-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v49-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v577-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\50\578-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v50-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v578-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\51\579-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v51-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v579-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\52\580-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v52-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v580-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\53\581-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v53-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v581-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\54\582-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v54-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v582-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\55\583-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v55-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v583-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\56\584-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v56-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v584-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\57\585-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v57-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v585-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\58\586-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v58-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v586-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\59\587-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v59-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v587-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\60\588-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v60-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v588-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\61\589-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v61-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v589-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\62\592-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v62-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v592-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{351497A7-6E40-3164-EBA3-CA9837145F7D}\63\538-{23C24B4A-9447-44D6-B724-48DD217D7B4B}-v63-{598E92ED-1A6B-4A60-A688-DD13862640FC}-v538-Downloaded.frx Status: Locked to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 Status: Invisible to the Windows API! Path: C:\Documents and Settings\Allen Sheena\Local Settings\Application Data\Microsoft\Silverlight\is\0xiguzad.nai\d105nl1a.ihf\1\s\5cgn4gembioxblnsomtczk513qzthc00ie5jfkem32xua5gn0faaahaa\f\LastLayout.bfcLayout:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Invisible to the WiSSDT ——————- #: 041 Function Name: NtCreateKey Status: Hooked by "Lbd.sys" at address 0xf74f087e #: 047 Function Name: NtCreateProcess Status: Hooked by "C:\Program Files\Norman\Ngs\Bin\nprosec.sys" at address 0xf75840d4 #: 048 Function Name: NtCreateProcessEx Status: Hooked by "C:\Program Files\Norman\Ngs\Bin\nprosec.sys" at address 0xf7584104 #: 053 Function Name: NtCreateThread Status: Hooked by "C:\Program Files\Norman\Ngs\Bin\nprosec.sys" at address 0xf75836fc #: 247 Function Name: NtSetValueKey Status: Hooked by "Lbd.sys" at address 0xf74f0bfe #: 257 Function Name: NtTerminateProcess Status: Hooked by "C:\Program Files\Norman\Ngs\Bin\nprosec.sys" at address 0xf7584488 #: 277 Function Name: NtWriteVirtualMemory Status: Hooked by "C:\Program Files\Norman\Ngs\Bin\nprosec.sys" at address 0xf7584134

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI